PT-2026-35063 · 4Gaboards · 4Gaboards

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-41418

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions 4ga Boards versions prior to 3.3.5
Description 4ga Boards is a boards system for realtime project management. The software allows user enumeration through a timing side-channel in the login endpoint '/api/access-tokens'. The server responds significantly faster when an invalid username or email is provided compared to when a valid one is used with an incorrect password. This difference occurs because the server executes the bcrypt.compareSync() function only when a valid user is identified, creating a detectable timing gap that can be used to verify the existence of users.
Recommendations Update to version 3.3.5.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-41418

Affected Products

4Gaboards